0.0

CVE-2024-57362 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation duplicate of CVE-2024-54840. Notes: All CVE users should reference CVE-2024-54840 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Feb. 3, 2025, 6:15 p.m.

6.8

CVSS3.1

CVE-2024-48806 -

Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Jan. 16, 2025, 7:15 p.m.

6.3

CVSS3.1

CVE-2024-54762 -

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: May 14, 2025, 6:26 p.m.

9.8

CVSS3.1

CVE-2023-28354 -

An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRP…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Jan. 10, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2024-13195 - donglight bookstore电商书城系统说明 HttpUtil.java getHtml server-side request forgery

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate…

📅 Published: Jan. 8, 2025, 11:31 p.m. 🔄 Last Modified: Aug. 22, 2025, 9:41 p.m.

5.3

CVSS4.0

CVE-2024-13194 - Sucms admin_members.php sql injection

A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…

📅 Published: Jan. 8, 2025, 11:31 p.m. 🔄 Last Modified: June 5, 2025, 7:45 p.m.

5.3

CVSS4.0

CVE-2024-13193 - SEMCMS Image Library Management Page SEMCMS_Images.php sql injection

A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The e…

📅 Published: Jan. 8, 2025, 11 p.m. 🔄 Last Modified: April 4, 2025, 4:59 p.m.

5.3

CVSS4.0

CVE-2024-13192 - ZeroWdd myblog BlogController.java update cross site scripting

A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/BlogController.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exp…

📅 Published: Jan. 8, 2025, 11 p.m. 🔄 Last Modified: June 5, 2025, 7:44 p.m.

5.3

CVSS4.0

CVE-2024-13191 - ZeroWdd myblog uploadController.java upload unrestricted upload

A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack may be init…

📅 Published: Jan. 8, 2025, 10:31 p.m. 🔄 Last Modified: May 28, 2025, 8:11 p.m.

0.0

CVE-2025-0351 -

Voluntarily withdrawn

📅 Published: Jan. 8, 2025, 10:16 p.m. 🔄 Last Modified: Nov. 19, 2025, 9:35 a.m.
Total resulsts: 344045
Page 6707 of 34,405
« previous page » next page
Filters